Skip to content
Fixedmark

FIXEDMARK · STATIC IP PROXY · EARLY ACCESS

Dedicated static outbound IPs for Vercel, Heroku, Railway, and other serverless apps.

Fixedmark sends your app's outbound traffic from two fixed IPv4 addresses reserved for you. Allowlist them once with your bank, broker, database, or partner API. Keep deploying where you deploy now.

Not live yet. Planned pricing: free tier, dedicated IP pair from $29/mo.

Why Fixedmark

How Fixedmark's planned launch compares with QuotaGuard, Fixie, and an AWS NAT Gateway.

What is Fixedmark?

Fixedmark is a static outbound IP proxy for serverless and PaaS apps. Your app sends HTTP, HTTPS, and SOCKS5 traffic through one proxy URL. Every request leaves from the same pair of IPv4 addresses. Allowlist the pair once. It stays the same across deploys, scaling, and platform moves.

  1. 01

    Allowlist once

    Give banks, brokers, and partner APIs one IP pair. It does not change when you redeploy.

  2. 02

    Keep your stack

    Stay on Vercel, Heroku, Railway, Render, Supabase, or Fly.io. Add one environment variable.

  3. 03

    Reach protected services

    Connect to IP-restricted APIs over HTTPS and to databases like Postgres and MongoDB over SOCKS5.

How it works

Get a static outbound IP in three steps.

  1. 01

    Create your endpoint

    Pick a region such as Mumbai or Frankfurt and get your IP pair.

  2. 02

    Configure your proxy

    Set FIXEDMARK_PROXY_URL and pass it to your HTTP client.

  3. 03

    Allowlist your IPs

    Add both IPs to the service you are connecting to.

curl --proxy "$FIXEDMARK_PROXY_URL" \
  https://api.example.com/v1/status

One proxy URL.
HTTP or SOCKS5.

Set FIXEDMARK_PROXY_URL and pass it to your HTTP client. Use HTTP CONNECT over a TLS proxy endpoint for APIs. Use SOCKS5 for databases and other TCP services.

Read the proxy quickstart

When you need a static IP

Common reasons teams need a fixed outbound IP.

Planned for launch

Nothing is live yet. These features are planned for the first public version. Some depend on the plan.

All features and roadmap
  • Dedicated IP pairs

    Two static IPv4 addresses reserved for your account only, load-balanced for high availability. Allowlist both once.

  • HTTP, HTTPS, and SOCKS5 in one plan

    HTTP CONNECT for APIs and SOCKS5 for databases, SSH, and any TCP service. One subscription, one set of IPs.

  • Zero-knowledge by default

    TLS passes through end to end and is never decrypted. A TLS-wrapped proxy endpoint keeps your proxy credentials off the wire in cleartext.

  • India and Asia regions

    Mumbai, Chennai, and Bangalore, plus Singapore, Jakarta, Tokyo, Sydney, Frankfurt, and the US, for low latency to Indian bank, broker, and partner APIs.

  • Connection logs

    See destination, SNI, bytes, egress IP, and result for every connection, so allowlist errors are easy to debug.

  • Destination allowlists

    Restrict each token to the hosts and ports it needs, such as api.razorpay.com:443. A leaked token cannot reach anything else.

  • bm tunnel CLI

    Forward local ports to IP-restricted databases for drivers without proxy support. Works from a local config file with no startup API call.

  • Usage alerts and webhooks

    Soft limits with alerts before you hit them, plus webhooks for quota and IP health events.

Dashboard preview

Planned dashboard: your IPs, proxy URL, and usage in one place.

Active· Example data
Static IP
203.0.113.24
Proxy URL
https://mum.egress.fixedmark.com

Requests

Example data · Last 30 days

Interactive preview with example data and documentation-only IP addresses. It does not connect to a live account.

Regions near the APIs you call

Planned launch regions: Mumbai, Chennai, Bangalore, Singapore, Jakarta, Tokyo, Sydney, Frankfurt, New York, and Virginia. Pick the region nearest the API or database you call.

All regions

Planned pricing

In USD per month. Subject to change before launch.

Starter

For side projects.

$9/mo

  • Shared IP pair
  • 50,000 requests
  • 20 GB bandwidth
  • HTTP, SOCKS5, and tunnel CLI
  • Usage alerts
Join early access

ProRecommended

For production apps.

$29/mo

  • Dedicated IP pair, 1 region
  • 500,000 requests
  • 200 GB bandwidth
  • 7-day connection logs
  • Webhooks
Join early access

Business

For teams with compliance needs.

$79/mo

  • Dedicated IP pairs, 2 regions
  • 2,000,000 requests
  • 1 TB bandwidth
  • Destination allowlists
  • 30-day connection logs
  • Priority support
Join early access

Free and Scale plans are also planned. Compare all planned plans

Static IP questions

What is Fixedmark?

Fixedmark is a static outbound IP proxy for serverless and PaaS apps, operated by BitMask LLP in India. Your app sends outbound requests through a Fixedmark proxy URL, and they leave from two fixed IPv4 addresses that you allowlist once. It is in early access and not yet live.

What is a static outbound IP?

It is the fixed public address other services see when your app makes a request. By default, serverless and PaaS platforms send traffic from shared IPs that change, so a bank, broker, database, or partner API cannot allowlist them. A static outbound IP stays the same across deploys.

How do I get a static IP for Vercel, Heroku, or Railway?

Route the requests that need a fixed IP through a proxy. With Fixedmark, set FIXEDMARK_PROXY_URL as an environment variable, pass it to your HTTP client, and add your two Fixedmark IPs to the destination's allowlist. The same setup works on Render, Supabase Edge Functions, Fly.io, and AWS Lambda.

How is Fixedmark different from QuotaGuard, Fixie, or an AWS NAT Gateway?

Fixedmark plans a dedicated IP pair on the $29/mo Pro plan. QuotaGuard's cheapest dedicated-IP plan is $219/mo. Fixie sells HTTP and SOCKS5 as separate subscriptions; Fixedmark includes both in one plan. A NAT Gateway only works inside your own AWS VPC, and two of them cost about $73/mo before traffic.

What is the difference between dedicated and shared static IPs?

A shared IP is used by several customers, so anyone on it passes the same allowlist. A dedicated IP is reserved for your account. On the planned plans, Free and Starter use a shared IP pair. Pro and above use a dedicated pair, which brokers and banks often require.

Does Fixedmark work for databases like Postgres, MySQL, and MongoDB?

Yes. Every plan includes SOCKS5, which carries any TCP connection, including Postgres, MySQL, MongoDB Atlas, Redis, and SSH. For drivers without proxy support, the bm tunnel CLI on paid plans forwards a local port to the IP-restricted database.

Does Fixedmark decrypt my traffic?

No. HTTPS passes through as an encrypted TLS tunnel from your app to the destination, so Fixedmark never sees request bodies, headers, or API keys. Connection logs record metadata only: destination host, SNI, bytes, egress IP, and result.

Is Fixedmark available now?

No. Fixedmark is in early access and not generally available. Join the early access list to get an endpoint when your region opens. Pricing is planned and may change before launch.

Make it fixed.

Fixedmark is in early access. Join the list to get a dedicated static IP pair when your region opens.